[FIX] replace eval() by safe_eval()

This commit is contained in:
Damien Crier
2015-09-04 09:51:04 +02:00
parent 457d5f1dd1
commit 97c10c1e46

View File

@@ -20,6 +20,7 @@
############################################################################## ##############################################################################
from openerp.osv import fields, orm from openerp.osv import fields, orm
from openerp.tools.safe_eval import safe_eval
from operator import itemgetter, attrgetter from operator import itemgetter, attrgetter
@@ -106,7 +107,7 @@ class EasyReconcileBase(orm.AbstractModel):
params = [] params = []
if rec.filter: if rec.filter:
dummy, where, params = ml_obj._where_calc( dummy, where, params = ml_obj._where_calc(
cr, uid, eval(rec.filter), context=context).get_sql() cr, uid, safe_eval(rec.filter), context=context).get_sql()
if where: if where:
where = " AND %s" % where where = " AND %s" % where
return where, params return where, params